Enterprise AI, cybersecurity, cloud and software for organizations worldwide.
Financial services

Cyber resilience exercises for financial institutions.

F Creative Studio 360 helps institutions in any country prepare for and run intelligence-led exercises, from readiness through to the record your team needs afterwards. Where CORIE applies, the work follows that framework.

A resilience exercise, not a standard penetration test.

CORIE (Cyber Operational Resilience Intelligence-led Exercises) is the framework published by the Council of Financial Regulators. Its members are the Australian Prudential Regulation Authority, the Australian Securities and Investments Commission, the Reserve Bank of Australia and the Treasury. Exercises use current threat intelligence to simulate how an adversary would pursue an objective, and they ask whether the institution can detect, respond and keep critical services running.

F Creative Studio 360 works with institutions worldwide. Choosing a provider is the institution’s decision. We do not replace your control group, and we do not submit reports to a regulator on your behalf. The scope follows the framework that applies to you: CORIE in Australia, TIBER-EU and DORA in Europe, or CBEST in the United Kingdom. A red team exercise or a penetration test is the better starting point when the question is narrower.

What F Creative Studio 360 does

Three pieces of work, used together or on their own, depending on how close the institution is to an exercise.

Readiness
A review of detection, response plans and the controls the exercise will lean on, mapped against the CORIE framework so gaps are visible before an exercise starts.
The exercise
An intelligence-led simulation aimed at a business objective. It looks at people, process and technology together, and at whether critical services would keep running.
Reporting and remediation
A record of what happened, what it means for resilience, and a practical order of work. Your team remains responsible for anything filed with a regulator.

How an engagement runs

The structure follows the framework that applies in your country. Our work sits inside the scope your control group agrees.

  1. 1

    Confirm the obligation

    Establish which framework applies in your country, what the objective is, and who on your side must authorise and oversee the exercise.

  2. 2

    Prepare

    Review response plans, detection and the systems that support critical services. Close the gaps that would make an exercise uninformative.

  3. 3

    Run the exercise

    Pursue the agreed objective within written rules. The point is what was prevented, what was detected, and how response and recovery actually worked.

  4. 4

    Debrief and remediate

    Walk leadership and the defending team through the narrative, then turn findings into a sequence of fixes and, where useful, a retest.

What you receive

  • A written scope and rules before any exercise activity.
  • A readiness view of detection, response and the services that must keep operating.
  • A narrative of the exercise and what it showed about resilience.
  • Findings rated by impact on critical services, with evidence.
  • A remediation sequence your team can run after the exercise.
  • Material your control group can use when it prepares its own regulatory reporting.

Who it is for

Banks, insurers, market infrastructure and other financial institutions in any country, including firms in banking and financial services. In Australia that includes institutions supervised by APRA. Preparing before a regulator sets a date is usually calmer than preparing after it.

Scenarios follow the behaviours described in the framework and, where useful, in MITRE ATT&CK. The measure of the work is resilience of the service, not a count of technical findings.

Common questions

What is CORIE?+

CORIE, Cyber Operational Resilience Intelligence-led Exercises, is the framework the Council of Financial Regulators uses for financial institutions and financial market infrastructure in Australia. The same kind of exercise is used elsewhere under other names, including TIBER-EU and CBEST. In each case the test uses threat intelligence to simulate how an adversary would operate, and it measures whether the institution can detect, respond, withstand and recover while protecting critical services and sensitive data.

How is this different from a penetration test?+

A penetration test looks for weaknesses that can be exploited in agreed systems. A CORIE-aligned exercise starts from an adversary objective and tests whether the institution can keep operating. F Creative Studio 360 also offers penetration testing and red teaming when those are the better fit.

Who is this for?+

Financial institutions in any country that need to show they can keep operating through a serious intrusion. If you are in Australia and in scope for CORIE, the exercise follows that framework. In the European Union the closest equivalents are TIBER-EU and DORA threat-led testing. In the United Kingdom it is CBEST. Elsewhere the exercise is scoped to the regulator and the critical services that apply to you.

Do you file the report with the regulator?+

No. F Creative Studio 360 prepares the exercise record and supports your team. The institution owns the relationship with its regulator, whether that is APRA, a European authority, the Bank of England or another supervisor, and it decides what is submitted.

Will the exercise disrupt services?+

The rules are written to avoid that. The aim is to learn whether critical services would survive, not to take them down. Anything that could affect operations is agreed in advance or left out of scope.

If an exercise is on the horizon, start with readiness.

F Creative Studio 360 will look at where you are against the framework and say whether the next step is preparation, an exercise, or a narrower test.